A players' union arrived at the athlete-data platform to investigate how its members' data was being handled. The platform had nothing to hide, its access controls were sound, its data accurate, its sharing rules strictly enforced, and its deletion process reliable. By every internal measure, it ran well.

None of that matters, when the customer had not come to be told the system was correct, it had come to be shown. Trust turned out to be the one thing the engineering team could not produce on demand.

The union meeting

What follows is a composite, but anyone who has sat on the engineering side of a meeting like it will recognise the pattern.

The union's representative opened with a simple question. The platform held biometric and performance data on every player he represented, and he wanted to know who could see it. The engineering lead had a good answer, access was role-based and enforced in the system rather than written in a policy and hoped for: medical staff saw medical data, coaching staff saw performance data, and nobody reached anything they were not entitled to. He said he believed her, and then he asked her to show him. For one named player, on one date, who had accessed his data, and why.